·Àsql×¢ÈëÀà
using System;
using System.Text.RegularExpressions;
using System.Web;
namespace FSqlKeyWord
{
/**//**//**//// <summary>
/// SqlKey µÄժҪ˵Ã÷¡£
/// </summary>
public class SqlKey
{
private HttpRequest request;
//private const string StrKeyWord = @"select|insert|delete|from|count(|drop table|update|truncate|asc(|mid(|char(|xp_cmdshell|exec master|netlocalgroup administrators|:|net user|""|or|and";
//string StrKeyWord1 = @"(like|and|exec|insert|select|delete|update|chr|mid|master|or|truncate|char|declare|join)".Replace("|",")|(");
private const string StrKeyWord = @"( like | and | exec |insert|select|delete|update|chr|mid|master| or |truncate|char|declare|join|exec master|xp_cmdshell|net user|systypes|sysobjects)";
//private const string StrRegex = @"([-|;|,|/|(|)|[|]|}|{|%|@|*|!|'])";
private const string StrRegex = @"--|'|@|!";
public SqlKey(System.Web.HttpRequest _request)
{
//
// TODO: ÔÚ´Ë´¦Ìí¼Ó¹¹Ô캯ÊýÂß¼
//
this.request = _request;
}
public SqlKey()
{
//
// TODO: ÔÚ´Ë´¦Ìí¼Ó¹¹Ô캯ÊýÂß¼
//
//this.request = _request;
}
/**//**//**//// <summary>
/// Ö»¶ÁÊôÐÔ SQL¹Ø¼ü×Ö
/// </summary>
public static string KeyWord
{
get
{
return StrKeyWord;
}
}
/**//**//**//// <summary>
/// Ö»¶ÁÊôÐÔ¹ýÂËÌØÊâ×Ö·û
/// </summary>
public static string RegexString
{
get
{
return StrRegex;
}
}
/**//**//**//// <summary>
/// ¼ì²éURL²ÎÊýÖÐÊÇ·ñ´øÓÐSQL×¢Èë¿ÉÄܹؼü×Ö¡£
/// </summary>
/// <param na
Ïà¹ØÎĵµ£º
¡¾ÎÄÕ±êÌâ¡¿±àд
SQL
²éѯµÄ¹Ø¼ü—
SQL
Óï¾äµÄÖ´ÐÐ˳Ðò
¡¾ÎÄÕÂ×÷Õß¡¿Ôø½¡Éú
¡¾×÷ÕßÓÊÏä¡¿
zengjiansheng1@126.com
¡¾×÷Õß
QQ
¡¿
190678908
¡¾×÷Õß
MSN
¡¿
zengjiansheng1@hotmail.com
¡¾×÷Õß²©¿Í¡¿
blog.csdn.net/newjueqi
*********************************************************** ......
ÔÚÊý¾Ý¿â¿ª·¢¹ý³ÌÖУ¬µ±Äã¼ìË÷µÄÊý¾ÝÖ»ÊÇÒ»Ìõ¼Ç¼ʱ£¬ÄãËù±àдµÄÊÂÎñÓï¾ä´úÂëÍùÍùʹÓÃSELECT INSERT Óï¾ä¡£µ«ÊÇÎÒÃdz£³£»áÓöµ½ÕâÑùÇé¿ö£¬¼´´Óijһ½á¹û¼¯ÖÐÖðÒ»µØ¶ÁÈ¡Ò»Ìõ¼Ç¼¡£ÄÇôÈçºÎ½â¾öÕâÖÖÎÊÌâÄØ£¿ÓαêΪÎÒÃÇÌṩÁËÒ»ÖÖ¼«ÎªÓÅÐãµÄ½â¾ö·½°¸¡£
1.1 ÓαêºÍÓαêµÄÓŵã
ÔÚÊý¾Ý¿âÖУ¬ÓαêÊÇÒ»¸ö ......
×î½üѧSQL Server2005£¬ÏÂÔØÁËSQL2005ÖÐÎÄ¿ª·¢°æ£¬µ«ÊÇͬѧÃǶ¼°²×°ÉÏÁË£¬Î¨¶ÀÎҵĻúÆ÷°²×°²»ÉÏ¡£
ÿ´Î°²×°DATABASEµÄʱºò¶¼ÌáʾÎÞ·¨Æô¶¯sqlservr.exe·þÎñÎÞ·¨Æô¶¯£¬ÖØװϵͳҲ²»ÐУ¬WINXP WIN 7ÏÂÃ涼ÎÞ·¨°²×°£¬ÓÚÊÇÉÏÍø²éÁËÏ£¬ÔÀ´SQL2005²»Ö§³Ö3ºË´¦ÀíÆ÷£¬Î¢ÈíÒ²×Ô ......
·Ï»°ÉÙ˵,(ÒѾÓоä·Ï»°ÁË.)
¿´±í
Óï¾ä: SELECT * from C
//---------------------------------------
Cno Cname Teacher
---- ---------- --------
1 ÓïÎÄ Æî¾²
2 &n ......
1) ʱ¼äת»»º¯ÊýÖÐÈç¹ûÓÐʱ¼ä±äÁ¿yyyy-mm-ddÁ½±ßÐèÁ½''
to_date(''' || to_char(a_valid_date_end, 'yyyy-mm-dd') ||''', ''yyyy-mm-dd'')
2) select distinct(e.itemnum) bulk collect into v_itemnum
½«×Ö·û´®Êý×éÒÔ·Ö¸ô·û·Ö¸ôµÄ×Ö·û´®µ÷ÓÃ
pkg_maximo_common.get_string(v_itemnum, ',', '')
3) unionÖ»Êǽ«Á½¸ö½á¹ ......